This is a read-only archive. No new posts or registrations. Privacy Page
Software

Mysterious Services

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi everyone!

This question pertains to a Dell Laditude laptop running WinXP Pro, I can provide full hardware specs if desired. As the description states I removed some offending services from this laptop in response to what appeared to be a stock trojan-drop type infection.

In the course of scrubbing the machine I noticed Service Control Manager errors at each login for the last month. This was disconcerting because the user only complained of performance issues as of yesterday.

The services in question would fail to start because their associated source files were not found. Normally I google any service, process, or other item that I don't immediately recognize, which is a very effective way of dealing with threats that don't randomize their names. The 3 services in question could not be found with thorough searching:

pptcpp2kui
sympolwwwqwe
r2scdeecp

Some interesting things to note here:

Only the sym* service appeared in the Services MMC, the other 2 were not present in the list. All info about it was labelled "unknown" by both MMC and HJT. The MMC setting for this service was set to "Manual" and it was not running at the time of debug.

Once I used HJT to remove the sym* service, the machine would reboot a couple of times with an NTLDR error "Missing Operating System." A cold reboot would resovlve this one. After a couple tries of that with the same result I dove into the registry and found each one of the offending services in HKLM in a couple of ControlSet00X sections. After careful export/remove operations of all keys using those service names (including some in the LEGACY sections which required permissions editing to remove) the machine behaves as it should so far.

I'll post code for the keys that display what "drivers" they were trying to either load or pretend to be:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\R2scdeecp]
"ErrorControl"=dword:00000001
"Type"=dword:00000002
"Group"="PNP_TDI"
"Tag"=dword:00000001
"ImagePath"="C:\\WINDOWS\\system32\\drivers\\msgpc.sys"
"Start"=dword:00000003

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\R2scdeecp\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,d8,00,af,00,f6,00,74,00,00,00,\
  99,00,00,00,9d,00,00,0a,0a,00,00,00,00,00,73,00,cd,00,2b,00,98,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\R2scdeecp\Enum]
"Count"=dword:00000000
"NextInstance"=dword:00000000
"INITSTARTFAILED"=dword:00000001


msgpc.sys is some sort of win2K QoS packet inspector or some such..

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Pptcpp2kui]
"ErrorControl"=dword:00000001
"Type"=dword:00000002
"Group"="PNP_TDI"
"Tag"=dword:00000001
"ImagePath"="C:\\WINDOWS\\system32\\drivers\\AMDAGP.SYS"
"Start"=dword:00000003

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Pptcpp2kui\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,d8,00,af,00,f6,00,74,00,00,00,\
  9a,00,00,00,44,00,00,0a,0a,00,00,00,00,00,16,00,95,00,f4,00,19,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Pptcpp2kui\Enum]
"Count"=dword:00000000
"NextInstance"=dword:00000000
"INITSTARTFAILED"=dword:00000001


Not certain what AMDAGP.SYS is, or if it is even legit.

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SYMPOLWWWQWA]
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SYMPOLWWWQWA\0000]
"Service"="Sympolwwwqwa"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="Sympolwwwqwa"


This one does not seem to have an "Image Path" defined.

All three keys were found in both ControlSet001 and ControlSet003. sym* was the only one found in ..\enum\LEGACY sections of those to control sets.

Has anyone got more information about these or possible ideas of their origin? This was on one of our web developers laptops, so any information on possible vectors for these would be excellent.

Thanks!

:scratch:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI